Download as pdf or txt
Download as pdf or txt
You are on page 1of 4

Audits That Work

Continuous Auditing: The basics, reality and the future.

By: Wa’el F. Bibi, CPA, CIA, CISA

We have heard the term “continuous auditing’’  The AICPA defines it as “the technologies
many times over the last few years, but do we and processes that allow an on-going re-
really know what it means? Is it the same as con- view and analysis of business information
tinuous control monitoring or continuous assur- on a real time basis. Continuous auditing
ance? Or is it a term used to describe the use of will require specialized skills of audit per-
Computer Assisted Audit Techniques (CAATs)? sonnel to monitor information electronical-
Have we tried to implement it, or know of some- ly and incorporate the use of intelligent
one who already done so? Is it for real, or just an- agents, computer modeling, and other
other fancy term auditors like to use? software tools. Continuous auditing will
give end users of information more timely
When I first heard of the term, the first thing that assurance that the information is correct
came to my mind was: real- time! To find out if and may eventually lead to continuous re-
this is a true presentation of the term, let’s first porting where financial information is up-
find out how continuous auditing is defined. dated and published as events occur.”
 A leading continuous auditing expert,
What is continuous auditing? Rutgers University professor Miklos Va-
sarhelyi, calls it "an audit that happens
immediately after or closely after a partic-
There are many definitions for continuous audit-
ular event."
ing; a few of them are listed below:
From the above definitions, we can conclude that
 According to The Institute of Internal Au- the objective of continuous auditing is to provide
ditors' (The IIA) Global Technology Audit real or near real time reporting on audit issues, and
Guide (GTAG 3) continuous auditing is that technology plays a vital role in the success of
defined as any method used by auditors to the implementation of continuous auditing.
perform audit - related activities( includ- Now that we have an understanding of continuous
ing control and risk assessments) on a auditing, let’s review some of the definitions for
more continuous(occurring without inter- continuous control monitoring.
ruption) or continual (occurring at re-
peated intervals.) basis.
What is Continuous Control Monitoring?
 A 1999 research report co-sponsored by
the American Institute of Certified Public
Accountants (AICPA) and the Canadian  IIA’s GTAG 3 defines it as:
Institute of Chartered Accountants (CICA) “A process that management puts in
defines continuous audit as: “a methodol- place to ensure that its policies, proce-
ogy that enables independent auditors to dures, and business processes are operat-
provide written assurance on a subject ing effectively.”
matter using a series of auditors' reports  I read a definition in a KPMG publication
issued simultaneously with, or a short pe- which I thought provides a good overview
riod of time after, the occurrence of events of the term:
underlying the subject matter.’’ “Continuous control monitoring is an au-
tomated feedback mechanism for man-
agement to ensure that the systems and

© 2010 Bibi Consulting Inc. All rights reserved. Page 1

controls have been operating as designed which management has implemented continuous
and transactions are processed appro- monitoring.
priately.” The relationship can be illustrated as follows:
The above definitions are clear and suggest simi-
larities with continuous auditing. Both processes
use identical tools and methods to achieve similar
objectives. So, are we talking about one process
under different names duplicated by different par-

Differences between Continuous Auditing

and Continuous Control Monitoring:

Despite the similarities, there are few differences

between both processes, which can be summarized
as follows:
 The major difference lies in the ownership
of the process. Continuous auditing is a
process owned by the audit activity, while
management owns continuous control
monitoring. A 2008 Protiviti article further explains this re-
 According to a KPMG publication, conti- lationship by indicating that the two processes
nuous control monitoring is more frequent complement each other. It adds, “in fact, there
(e.g. hourly, daily, weekly) than conti- is often an inverse relationship between the ex-
nuous auditing (e.g. monthly, quarterly). tent of continuous monitoring performed by
Also the level of monitoring for continu- management and the need for continuous audit-
ous monitoring would be more granular ing. For example, if management is actively
and operational than continuous auditing, monitoring transactions and controls across a
which may be more focused on key con- range of business systems and processes, this
trols that provide assurance at the audit usually means that internal audit does not have
objective level. to perform the same continuous auditing activi-
 An ISACA article identified another dif- ties. As long as internal audit is able to assess
ference relating to the type and sufficiency the reliability and effectiveness of manage-
of evidence generated by both processes. It ment’s continuous monitoring then they can re-
describes the evidence obtained by audi- ly on those activities and reduce the extent of
tors as direct, while those obtained by audit testing. Internal audit can then focus on
management as indirect. It concludes that extending continuous auditing techniques to
due to the indirect nature of evidence those areas that are not monitored by manage-
gathered by management through continu- ment.”
ous control monitoring, it would not be Based on the above, can we assume that if
sufficient in a continuous auditing en- management does a superb job in performing
gagement if used alone. continuous control monitoring, this will lead to
a minimal continuous auditing and auditors’
role will be marginalized? Not necessarily, in
Relationship between Continuous Auditing fact this may provide an opportunity to internal
and Continuous Control Monitoring: auditors to focus on areas of high risk and on
overseeing the risk management and the conti-
According to IIA’s GTAG 3, there is an inverse nuous control monitoring processes.
relationship between the adequacy of manage-
ment’s monitoring and risk management activities What is Continuous Assurance?
and the extent to which auditors must perform de-
tailed testing of controls and assessment of risk. Continuous assurance is defined by the IIA as
The audit activity’s approach to, and amount of, the combination of continuous auditing and au-
continuous auditing depends on the extent to

© 2010 Bibi Consulting Inc. All rights reserved. Page 2

dit oversight of continuous control monitoring  Increased confidence in financial re-
by management. sults.

CAATs vs. Continuous Auditing: Who is implementing CA?

Computer assisted audit techniques (CAATs) The first model of continuous auditing was de-
refers to software used by auditors to enhance veloped by AT&T Bell Laboratories in 1989 to
the audit process. CAATs can be classified into evaluate the billing system within the company.
four broad categories: Since that time, CA has evolved and more or-
 Data analysis software ganizations have adopted it in the United States
 Network security evaluation soft- and Canada. A 2008 survey by KPMG shows
ware/utilities. that 26% of respondents indicated that they
 OS and DBMS security evaluation have already implemented CA, while 43% of
software/utilities respondents indicated there intent to implement
 Software and code testing tools. it during the coming three years.

Can an audit department claim that it adopts The above data suggest that CA is gaining mo-
continuous auditing just because it uses mentum, but also that organizations need to ac-
CAATs? The answer is no. The use of CAATs celerate its adoption. I have not seen data on the
is an essential part of the continuous audit application of CA outside the United States, but
process, but it is not a continuous audit by it- my feeling is that the rest of the world is way
self. To illustrate, the use of CAATs to review behind the U.S especially in the developing
accounts payable (data mining function) during countries including the Middle East.
a scheduled audit does not mean that an organi-
zation is implementing continuous auditing un- The Future:
less this review is performed on a continues or
continual basis and involves risk and control While most of the organizations around the
assessments. A one-time audit using CAATs world have not yet started to adopt and imple-
does not represent continuous auditing. ment continuous auditing, other organizations
are already looking beyond CA.
Prerequisites for Continuous Auditing: As with the trend of internal audit, continues
In order to implement an efficient and effective auditing will be shifting from a control –centric
continuous audit program, the following condi- model to a risk- centric model by adopting what
tions should exist; the IIA calls the Continuous Risk and Control
 Availability of proper technology at the Assurance (CRCA) model, which will takes
company and internal audit levels. continuous auditing and monitoring to a new
Continuous auditing is heavily depend- level. It is a top-down model that starts with en-
ent on technology. terprise goals and objectives, and moves on to
 Management support and buy-in. risks to the objectives, assessment and testing
 Accessibility of data. of the controls required to manage the risks,
 Competence of auditors. and data mining that can provide indicators of
risk and control health. The objective is to pro-
vide continuous risk and control assessment to
Benefits of Continuous Auditing: the management and board by taking real –time
A presentation by the IIA on GTAG 3 lists the audit technologies to the next level.
following benefits for CA:
 Increased scope of audit activities.
 Increased ability to mitigate risk.
 Reduced financial errors and potential
for fraud.
 Sustainable and cost – effective means
to support compliance and control as-

© 2010 Bibi Consulting Inc. All rights reserved. Page 3


- Global Technology Audit Guide (GTAG) Continuous Au-

diting: Implications for Assurance, Monitoring, and Risk
- IIA’s GTAG 3 presentation by Dave Coderre.
- Six Steps to an Effective Continuous Audit Process. Inter-
nal Auditor magazine, February 2008.
- Internal Audit: The Continuous ar-
ticle, September 2009.
- Information Systems Control Journal, Volume 5, 2002,
Continuous Auditing: Is It Fantasy or Reality?
KPMG ,Continuous Auditing and Continuous control
monitoring: Transforming Internal Audit and Management
- KPMG, Continuous Auditing and monitoring: using tech-
nology to drive value by managing risk and improving per-
Monitoring to Create Value.
- Continuous control monitoring and auditing :what is the
difference, John Verver, ACL Services ltd.
- SAP, A Look into the Future: The Next
Evolution of Internal Audit
Continuous Risk and Control Assurance.
Beyond Continuous auditing:Norman Marks.
- CICA website.
- ICPA website.

© 2010 Bibi Consulting Inc. All rights reserved. Page 4

You might also like